9.8
CVSSv3

CVE-2018-7300

Published: 22/02/2018 Updated: 14/04/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and previous versions allows remote malicious users to write arbitrary files to the device's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

eq-3 homematic_ccu2_firmware

Exploits

#!/usr/bin/ruby # Exploit Title: Homematic CCU2 Arbitrary File Write # Date: 28-03-18 # Exploit Author: Patrick Muench, Gregor Kopf # Vendor Homepage: wwweq-3de # Software Link: wwweq-3de/service/downloadshtml?id=268 # Version: 22923 # CVE : 2018-7300 # Description: atomic111githubio/article/homematic-ccu2-filewrite ...